The IAM Architect is responsible for designing and leading enterprise Identity & Access Management strategies across Identity Governance, Privileged Access Management, Workforce Identity, and Cloud Identity platforms. This role provides architectural leadership, establishes IAM standards, and drives large-scale IAM transformation initiatives aligned with enterprise security strategies.
Day to day responsibilities
IAM Architecture
- Define enterprise IAM architecture and technology roadmaps
- Design end-to-end identity solutions across workforce and privileged identities
- Develop IAM reference architectures, standards, and design patterns
- Lead solution design workshops with business and technical stakeholders
Identity Governance
- Architect Saviynt and SailPoint solutions
- Design identity lifecycle governance
- Define RBAC and ABAC strategies
- Design access certification and governance frameworks
Privileged Access Management
- Architect CyberArk, Delinea, and BeyondTrust solutions
- Define privileged access strategies
- Design privileged identity governance and operational models
Identity Platforms
- Architect Microsoft Entra ID solutions
- Design Okta Workforce Identity architectures
- Integrate cloud identity providers with enterprise applications
- Define federation, SSO, MFA, Conditional Access, Identity Protection, and Passwordless strategies
Program Leadership
- Lead multiple IAM implementation workstreams
- Provide architectural governance
- Mentor consultants and engineers
- Participate in solution estimation, proposal development, and customer presentations
- Collaborate with executive stakeholders on IAM strategy
Essential traits
Core Technical Skills
- 9–12 years of IAM experience
- Strong enterprise architecture experience across IAM domains
- Deep expertise in Saviynt and/or SailPoint
- Strong experience with CyberArk, Delinea, or BeyondTrust
- Extensive experience with Microsoft Entra ID
- Strong experience with Okta Workforce Identity
- Experience designing federation, SSO, MFA, Conditional Access, Identity Governance, and PAM solutions
- Experience developing enterprise IAM roadmaps
Technical Foundations
- Identity governance and administration
- Privileged Access Management
- Authentication and federation (SAML, OAuth2, OIDC, SCIM)
- Active Directory and LDAP
- Cloud identity architecture
- API integrations
- Zero Trust security architecture
Prerequisites
Bachelor's degree in Computer Science, Information Technology, Cyber Security, or equivalent practical experience.
- Experience leading enterprise IAM transformation programs
- Experience in consulting or professional services organizations
- Experience with cloud platforms (Azure, AWS, GCP)
- Strong understanding of security frameworks such as NIST and CIS
- Microsoft, Okta, Saviynt, SailPoint, CyberArk Certifications
#LI-Hybrid
#LI-SP1
Skills Required
- 9-12 years of IAM experience
- Enterprise IAM architecture experience across IAM domains
- Deep expertise in Saviynt and/or SailPoint
- Strong experience with CyberArk, Delinea, or BeyondTrust
- Extensive experience with Microsoft Entra ID
- Strong experience with Okta Workforce Identity
- Experience designing federation, SSO, MFA, Conditional Access, Identity Protection, and Passwordless solutions
- Experience designing identity lifecycle governance, access certification, RBAC and ABAC
- Experience developing enterprise IAM roadmaps and standards
- Experience leading enterprise IAM transformation programs
- Experience in consulting or professional services organizations
- Experience with cloud platforms (Azure, AWS, GCP)
- Strong understanding of security frameworks such as NIST and CIS
- Knowledge of authentication and federation protocols (SAML, OAuth2, OIDC, SCIM)
- Experience with Active Directory and LDAP and API integrations
- Familiarity with Zero Trust security architecture
- Bachelor's degree in Computer Science, IT, Cyber Security, or equivalent experience
- Microsoft, Okta, Saviynt, SailPoint, CyberArk Certifications
Kroll Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.
-
Healthcare Strength — Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
-
Retirement Support — A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
-
Leave & Time Off Breadth — Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.
Kroll Insights
What We Do
Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.

.jpeg)






